10

CVE-2026-57216

Exploit

RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect remotely when traffic is accepted through a trusted PROXY-protocol path and the backend listener is loopback-bound because the loopback check uses the listener-side socket address instead of the real client source. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Broadcom ≫ Rabbitmq Server Version >= 3.13.0 < 4.2.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.5% 0.401
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
security-advisories@github.com 6.8 2.2 4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6
Release Notes
https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-36m6-588r-vqcw
Vendor Advisory
Exploit
https://github.com/rabbitmq/rabbitmq-server/pull/15936
Patch
Issue Tracking
https://github.com/rabbitmq/rabbitmq-server/pull/15940
Patch
Issue Tracking
https://github.com/rabbitmq/rabbitmq-server/commit/7273c9eb6920abcde17b892dbe97ccaf906ead47
Patch
https://github.com/rabbitmq/rabbitmq-server/commit/9f8c39fcf0acbc43080ee7017a62a02832114112
Patch